Age | Commit message (Collapse) | Author | |
---|---|---|---|
2009-06-01 | Don't throw an error if there are no visible tags. | Bharat Mediratta | |
2009-06-01 | Security pass over all controller code. Mostly adding CSRF checking | Bharat Mediratta | |
and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched. | |||
2009-06-01 | Switch the default login page to non-ajax mode. It looks awful, but better ↵ | Bharat Mediratta | |
than before. | |||
2009-06-01 | Fix a place where I shouldn't have renamed "core" to "gallery", breaking ↵ | Bharat Mediratta | |
maintenance mode. | |||
2009-06-01 | use PHP_SAPI instead of php_sapi_name() | Bharat Mediratta | |
2009-06-01 | Don't bomb if there are no exif_records for the given item. | Bharat Mediratta | |
2009-06-01 | Normalize the random values used in the blocks_dashboard_xxx vars so | Bharat Mediratta | |
that install.sql is more stable. | |||
2009-06-01 | Do a little cleanup and get rid of code left-over from when this | Bharat Mediratta | |
controller rendered HTML. Also, catch all exceptions at the root level and restore the change in 84ce0cdefda162917c7b01722a7259ac52c4e30d which appears to have gotten lost in the shuffle. | |||
2009-05-31 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
2009-05-31 | Move the sql packaging code from installer into the gallery module. It must ↵ | Tim Almdal | |
be run from the command line and will throw a 404 if it is run as a web request. | |||
2009-05-31 | Clear the site status message on deactivate, not on uninstall. | Bharat Mediratta | |
2009-05-31 | Don't let relative_path() try to update the database if the Item_Model | Bharat Mediratta | |
is not loaded, else you get weird errors. | |||
2009-05-31 | Accidentally broke the AllowOverride info url in the migration from | Bharat Mediratta | |
core -> modules/gallery. Fixed, and incidentally make the link appear in a new tab/window. | |||
2009-05-31 | Remove extra blank line | Bharat Mediratta | |
2009-06-01 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
2009-06-01 | Convert %7E to ~ when proxying files to work around Firefox's overzealous ↵ | bharat | |
security model. | |||
2009-05-31 | Merge branch 'master' of git://github.com/gallery/gallery3 | Bharat Mediratta | |
2009-05-31 | Properly call user::login when we automatically login the admin user | Bharat Mediratta | |
immediately after install. Fixes ticket #323. | |||
2009-06-01 | Fix a warning | bharat | |
2009-06-01 | Change E_NONE -> 0 .. turns out E_NONE is a figment of my imagination ↵ | bharat | |
according to http://us.php.net/manual/sl/function.error-reporting.php | |||
2009-05-31 | Update for changes to admin_users_group.html.php | Bharat Mediratta | |
2009-05-31 | Localize a string | Bharat Mediratta | |
2009-05-31 | user admin facelift | jhilden | |
* added drag & drop help message for empty groups * fixed overflow issue with more than ~10 members in one group * CSS improvements | |||
2009-05-31 | Relax the regex we use to extract the movie size so that it works with | Bharat Mediratta | |
the new version of ffmpeg that I have on my dev box (ffmpeg 0.5-svn17737+3:0.svn20090303-1) | |||
2009-05-31 | Switch to using html::specialchars() for cleaning. | Bharat Mediratta | |
2009-05-31 | Updated for renamed variable | Bharat Mediratta | |
2009-05-31 | Merge branch 'master' of git://github.com/gallery/gallery3 | Bharat Mediratta | |
2009-05-31 | Rename "text" to "title" for clarity. | Bharat Mediratta | |
2009-05-31 | Xss scanner golden file. Up to date. | Bharat Mediratta | |
2009-05-31 | Run all variables containing user-entered text through p::clean() | Bharat Mediratta | |
2009-05-31 | Clean up view variables | Bharat Mediratta | |
2009-05-31 | Run all variables that come from user-entered data through p::clean() | Bharat Mediratta | |
2009-05-31 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
2009-05-31 | Update the clean/dirty format, check all ffiles instead of just one (which ↵ | Bharat Mediratta | |
was for debugging) | |||
2009-05-31 | Run p::clean() on any variables that contain data entered by users. | Bharat Mediratta | |
2009-05-31 | First pass at an XSS security test, along with the "p" helper which | Bharat Mediratta | |
can clean HTML output. | |||
2009-05-31 | Convert single quotes to double quotes | Bharat Mediratta | |
2009-05-31 | Remove the test images from the gallery module and move it to the developer ↵ | Tim Almdal | |
module in -contrib | |||
2009-05-31 | Add a / to the end of TMPPATH to match other paths. | Bharat Mediratta | |
Signed-off-by: Bharat Mediratta <bharat@menalto.com> | |||
2009-05-30 | Remove insertion of content via CSS, it's not supported by IE. Just added ↵ | Chad Kieffer | |
sufficient white space as a seperator. | |||
2009-05-30 | Fix width of add tag text input in IE | Chad Kieffer | |
2009-05-30 | Fix height on #gQuickPane in IE | Chad Kieffer | |
2009-05-30 | Fix IE issues with gPager, switch gPager from id to class, it's possible ↵ | Chad Kieffer | |
that we might want it to appear more than once in views. | |||
2009-05-30 | Add transparency for overlay in IE 7 and 8 | Chad Kieffer | |
2009-05-30 | Focus IE fixes on versions less than 8 | Chad Kieffer | |
2009-05-30 | gate $can_edit and $can_add on whether or not we have an $item at all | Bharat Mediratta | |
(fixes a bug where search doesn't render because it has no item). | |||
2009-05-30 | Add a / to the end of TMPPATH to match other paths. | Bharat Mediratta | |
2009-05-30 | Use short hex for colors, #cccccc > #ccc | Chad Kieffer | |
2009-05-30 | Refine link colors a bit. Drop orange for hover. Remove underlines for ↵ | Chad Kieffer | |
sf-menu hovers. | |||
2009-05-30 | White space fixes | Chad Kieffer | |